The emails hide a new variant of a Trojan downloader

Nov 4, 2013 12:31 GMT  ·  By

Internauts are advised to act with caution in case they come across an email in their inbox that’s entitled “Direct Debit Seminar Invite” and appears to come from National Westminster Bank, or NatWest.

Experts warn that these fake notifications are being sent out by cybercriminals in an effort to distribute malware.

The emails are sent from a spoofed Better Business Bureau (BBB) address, [email protected], and they read something like this:

“Good morning,

Please find attached the above, which I thought that you maybe interested in attending.

Kind Regards. Graham Nevin Senior Relationship Manager Commercial Banking NatWest.”

According to MX Lab experts, the file that’s attached to these messages is not an invitation, but a Trojan downloader that retrieves other threats onto the infected computer.

If you’re already a victim of this attack, make sure you regularly scan your computer with an updated antivirus. When researchers first spotted these emails, the Trojan wasn’t detected by any antiviruses, but after a few definition updates, it’s likely that the malware will be identified.